7.8

CVE-2026-68419

RDMA/irdma: Prevent rereg_mr for non-mem regions

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Prevent rereg_mr for non-mem regions

When a QP/CQ/SRQ is created, a two step process is used
where the buffer is allocated in userspace and explicitly
registered with the normal reg_mr mechanism prior to creating
the actual QP/CQ/SRQ object.

These special registrations are indicated via an ABI field
so the driver knows that they do not have a valid mkey and
to skip the actual CQP command submission.

Since these are real MR objects from the core's perspective,
it is possible for a user application to invoke rereg_mr on them
and cause a real CQP op to be emitted with the zero-initialized
mkey value of 0.

Fix this by preventing rereg_mr on these special regions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 715fdb3b30541cc8180b7cdc6aa9f8c307afdf25
Version < fb46d134e1b8690bed2da9005b36d32d2efd34ac
Status affected
Version 5ac388db27c443dadfbb0b8b23fa7ccf429d901a
Version < b5029e91c63406e4f4c8d58161048b41b6f0bd8c
Status affected
Version 5ac388db27c443dadfbb0b8b23fa7ccf429d901a
Version < ca1c29f05274b737dc964e28b97803750d7cf7ec
Status affected
Version 5ac388db27c443dadfbb0b8b23fa7ccf429d901a
Version < dbaa37e060918c45517786e37ecab0f300b48fa9
Status affected
Version 5ac388db27c443dadfbb0b8b23fa7ccf429d901a
Version < a846aecb931b4d65d5eafa92a0623545af46d4f2
Status affected
Version 6.6.120
Version < 6.6.148
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fb46d134e1b8690bed2da9005b36d32d2efd34ac
https://git.kernel.org/stable/c/b5029e91c63406e4f4c8d58161048b41b6f0bd8c
https://git.kernel.org/stable/c/ca1c29f05274b737dc964e28b97803750d7cf7ec
https://git.kernel.org/stable/c/dbaa37e060918c45517786e37ecab0f300b48fa9
https://git.kernel.org/stable/c/a846aecb931b4d65d5eafa92a0623545af46d4f2